Syft and Trivy reported 43.78% and 32.71% of lockfile packages across 2,050 JavaScript repositories in an Inria and ANSSI study, against 98.72% for cdxgen. The tool, its version and its flags decide what an SBOM lists, so that recipe belongs under version control.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
ANSSI says stolen staff passwords let an attacker take data on about 600,000 French taxpayers and firms, and the theft went undetected for seven weeks. Its report blames password-only portals, a flat government network and a reset that left the attacker's session open.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap0
- Incentives40
- Confidence68
ANSSI says an attacker used dozens of stolen DGFIP staff passwords on password-only portals to take data on over 600,000 French taxpayers and businesses. For other operators, the fixes are login checks on devices they do not manage and a password reset that also ends live sessions.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence55
678,000 DGFiP records are being marketed with names, addresses and income figures together. France logged 33 of CertiK's 52 verified physical coercion attacks on crypto holders in H1 2026.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+25
- Incentives40
- Confidence60
France's tax authority says an intruder used a stolen or misused identity to reach its systems in late June and extract data on individuals and businesses before access was cut.
Perspective Coverage
6 publishers
- Builder
- Builder 28%
- Operator
- Operator 62%
- Investor
- Investor 10%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+10
- Incentives60
- Confidence68
The G7 Cyber Security Working Group's June call to action says the quantum threat is off the radar and under-resourced at most organizations, and it hands CISOs the wording to fund a cryptographic inventory this cycle.
Perspective Coverage
5 publishers
- Builder
- Builder 22%
- Operator
- Operator 55%
- Investor
- Investor 23%
Reality
- Evidence72
- Adoption30
- Hype gap+10
- Incentives60
- Confidence68
French notaries lost the money to intruders who lived on their networks and edited payment details before the instructions went out, which is why bank-side verification kept waving the transfers through.
Publishers:csn.notaires.fr · news.risky.biz · risky.biz Perspective Coverage
3 publishers
- Builder
- Builder 13%
- Operator
- Operator 77%
- Investor
- Investor 10%
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+5
- Incentives20
- Confidence55
From 11 September 2026, an actively exploited vulnerability starts a 24-hour early warning, a 72-hour notification and a 14-day final report, all timed from awareness. The artifact that decides whether you make it is your SBOM archive.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+15
- Incentives50
- Confidence60
France's ANSSI spent two years quietly evicting a crew that had been altering payment instructions inside notary networks. The procedural fix that landed takes bank details off email rather than checking whether they changed.
Reality
- Evidence45
- Adoption58
- Hype gap−20
- Incentives42
- Confidence50
A Forbes Tech Council argument for urgency leans on benchmarks that were never factoring runs. The part of it that survives scrutiny is still enough to justify the spend.
Reality
- Evidence38
- Adoption36
- Hype gap+42
- Incentives78
- Confidence48
DGFiP says the intruder used a stolen employee identifier and an authorised third party's credentials, and claimed to bypass MFA. No zero-day was involved.
Reality
- Evidence63
- Adoption71
- Hype gap+12
- Incentives74
- Confidence58